In July 2019, Proofpoint reported a new malware campaign named, “Operation Lagtime IT.” The campaign is targeting government agencies in East Asia and leveraging malicious RTF documents to deliver multiple payloads, including a new custom malware payload dubbed, “Cotx RAT.”
To read the full article in our portal, and find an archive of related reporting, follow this link to - https://redskyalliance.org
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Monday, September 9, 2019
Monday, August 26, 2019
Cryxos Trojan Malware Uptick
Hackers can program Trojans like Cryxos to accomplish pretty much anything they want. In August 2019, Wapack Labs observed a significant uptick in malicious emails delivering a malware identified as Cryxos. The observed malware is currently being delivered to users in Brazil, however, thousands of related specimens were observed on Virus Total indicating a widespread campaign affecting multiple countries.To read the full article in our portal, and find an archive of related reporting, follow this link to - https://redskyalliance.org/finished-analysis/cryxos-variant
Monday, June 17, 2019
Newly Identified Phishing Malware, Allantibots, Can Fool Even The Most Eagle-eyed User.
Apple IDs are a popular target for hackers because they can enable theft of financial data and other personally identifiable information (PII). These are often obtained through phishing campaigns intended to trick users into entering their personal data. In June 2019, Wapack Labs identified one such campaign that is leveraging a large infrastructure and a phishing kit dubbed ‘Allantibots’. Allantibots is a sophisticated phishing package and is characterized by its ability to spoof the Apple URL. This results in a phishing URL that looks completely legitimate, even to a cautious user. To read the article go here: https://redskyalliance.org/finished-analysis/allantibotsTo read the full article and find an archive of related cyber reporting, follow this link to Allantibots Article
Be sure to check out our cyber portal for other related articles Red Sky Alliance.org
Labels:
Allantibots,
apple,
AppleIDs,
CFO,
CISSO,
cyberattack,
financial,
financialreporting,
Hacking,
malware,
Phishing
Thursday, May 23, 2019
Mirai A Self-propagating Mutating Bot Malware
In May 2019, Wapack Labs performed an inventory of recent Mirai specimens on Virus Total. A total of 29K malware specimens were observed during the period spanning from early March to mid-May 2019. A comprehensive indicator list is provided as a companion document to this product.
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
Thursday, November 8, 2018
LoJax Malware
Cybersecurity researchers have unveiled, the first-ever, UEFI (Unified Extensible Firmware Interface) rootkit being used. It allows hackers to implant persistent malware on targeted computers that could endure a complete hard-drive wipe. Titled LoJax, the UEFI rootkit is part of a malware campaign conducted by the Sednit group, also known as APT28, Fancy Bear, Strontium, and Sofacy, who have targeted government organizations in the Balkans as well as in Central and Eastern Europe.[1] The Sednit group is a state-sponsored hacking group believed to be a unit of the Russian GRU (General Staff Main Intelligence Directorate). The hacking group has been associated with a number of high-profile attacks, including the DNC hack during the US 2016 presidential election.
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
Tuesday, October 30, 2018
InfusedAppe Malware
InfusedAppe malware was observed by Wapack Labs attempting an Apache Struts CVE-2017-5638 exploit against a client network. The malware is titled InfusedAppe because it writes several files to C:\Windows\InfusedAppe\ upon execution of the executable payload.
InfusedAppe follows Chinese preference for multi-stage payloads. Its configuration suggests plans to expand in targeting US and Republic of Korea (KR) users.
Want to know more? Webinar tomorrow at Noon EST.
Contact Wapack Labs for more information:
603-606-1246, or feedback@wapacklabs.com
InfusedAppe follows Chinese preference for multi-stage payloads. Its configuration suggests plans to expand in targeting US and Republic of Korea (KR) users.
Want to know more? Webinar tomorrow at Noon EST.
REGISTER HERE
Contact Wapack Labs for more information:
603-606-1246, or feedback@wapacklabs.com
Friday, March 9, 2018
REMCOS Remote Administration Tool

REMCOS is a new, publicly available Remote Administration Tool (RAT) that has become popular with hackers. Since January 2018, over 14 hundred samples were submitted to Virus Total, indicating the RAT is growing in popularity. Recent changes to Tactics, Techniques, and Procedures (TTP) include embedding payloads in MP3 and JPEG files; resulting in little to no Antivirus (AV) detections and significantly increasing the likelihood for infections. The malware in this report downloads payloads embedded in other files with little or no current detections, which may indicate the possibility of a high infection rate...READ MORE
Wapack Labs has cataloged and reported on Remote Administration Tools in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Labels:
low detection,
malware,
RAT,
REMCOS,
remote access tool
Friday, February 9, 2018
AZORult Stealer
AZORult is a publicly available information-stealing malware that is popular among hackers. AZORult is delivered via phishing e-mails and with the use of Exploit Kits (EK), most notably the Rig EK. It collects information from victims by targeting a variety of applications for credential harvesting. In January 2018, Wapack Labs started analysis of AZORult nodes in an effort to identify stolen data. As part of this research, Wapack Labs gained insight into AZORult Command and Controls (C2). This report includes details on the AZORult malware and provides trending on the identified infrastructure. Wapack Labs analysts were able to recover over a million AZORult logs, which include data on victim IPs, e-mails, credentials, and attack server data. This information is listed in the Wapack Labs Blacklist Slack channel and searchable via our CTAC tool to provide situational awareness...READ MOREWapack Labs has cataloged and reported on AZORult malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
Labels:
AZORult,
C2,
hackers,
information stealing,
infrastructure,
malware
Thursday, January 4, 2018
The Iranian Cyber Evolution: RATs, Backdoors, and Droppers

Wapack Labs has been monitoring Iranian cyber activity for several years, specifically the evolving OilRig and Greenbug campaigns. Their adoption of a cyber operational paradigm involving both cyber hacktivism and cyber espionage tactics resembles cyber activity patterns employed by Chinese APT groups, whereby different groups perform different campaigns, with multiple teams conducting separate phases of a cyber campaign. With President Trump’s refusal to re-certify Iran’s compliance with the 2015 Iran nuclear agreement, Wapack analysts are researching the continued efforts of Iranian-backed cyber threats in order to detect and defend against next moves.
One common attribute is that they all engage in prolonged reconnaissance campaigns of their targets; at times lasting over a year. Greenbug, a cyber-espionage group with suspected Iranian ties, has been dynamically progressing in such campaigns. In August 2017, a Greenbug tool, dubbed ISMAgent (an ISMDoor variant), resurfaced in the wild to harvest account credentials. Wapack Labs discovered evidence of ISMDoor variants relying on the VB:Trojan.Valyria (possibly Clayside) for delivery, linking Greenbug to another group of Iranian actors known as OilRig. Wapack Labs assesses with moderate confidence that recent activity involving ISMDoor is an indicator of the ramping up of another cyber campaign cycle...READ MORE
Wapack Labs has cataloged and reported on Iranian cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Labels:
cyber threat,
greenbug,
hacktivism,
Iran,
malware
2018 Cyber Security Threat and Vulnerability Predictions

This report encapsulates our predictions regarding the most significant cyber threats and vulnerabilities for 2018.
- Phishing: Will likely become more popular among novice and criminal hackers.
- Account Targeting: Account credentials are increasingly more available.
- Democratization of Cyber Weapons: 2017 saw the most high-profile ransomware attack to-date with the Wannacry worm.
- Tor Network: 2018 is the year of fighting and winning against the abuse of the Tor network.
- Macro Malware: The popularity of malicious macros for malware delivery continued strong in 2017.
- Geopolitical Tensions: Iran and North Korea tensions continue.
- Blockchain-related Cybercrime: With the establishment of Bitcoin futures and general interest to blockchain technologies, exploitation in this field grows too...READ MORE
Wapack Labs has cataloged and reported on cyber threats and vulnerabilities in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
WWW.WAPACKLABS.COM
Labels:
2018,
blockchain,
cyber threats,
malware,
Phishing,
predictions,
TOR,
vulnerabilities
Thursday, December 21, 2017
Terdot Banking Trojan
TLP AMBER ANNOUNCEMENT:Terdot is a multipurpose banking trojan developed using Zeus source code leaked in 2011. The latest version of Terdot surfaced in 2016 and incorporates new surveillance capabilities. Now that the Terdot trojan features cyber espionage capabilities it is more likely to be sought after by attackers. Like its predecessor Zeus, some of Terdot's features and configurations indicate a high likelihood of Russian origins. This report examines Terdot’s new capabilities, infrastructure, attribution and delivery mechanisms...READ MORE
Wapack Labs has cataloged and reported on banking trojans in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
This TLP AMBER report is available only to Red Sky Alliance members.
Monday, November 27, 2017
Google Images Technical Support Scams

In two separate instances, Wapack Labs has reported technical support scams. Upon examining these scams, Wapack Labs observed other products being targeted by scammers. Performing a Google Image search for “<technology product> technical support” yields images with phone numbers for technical support. Upon performing basic OSINT collection against these phone numbers, it is apparent these phone numbers are involved in scams. Scammer tactics routinely offer a Remote Desktop Support to troubleshoot the devices. Some of these scams charge monthly fees for remote support services, but do not actually fix technical problems, and others are solely for dropping malware during the Remote Desktop session. The malware dropped during the Remote Desktop sessions will often include free or cracked version of keyloggers and other novice data/credential exfiltration tools...READ MORE
Wapack Labs has cataloged and reported on technical support scams in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
Labels:
Fraud,
malware,
scam,
technical support
Tuesday, November 21, 2017
Gibon Ransomware Analysis

TLP AMBER ANNOUNCEMENT:
Wapack Labs analysts recently observed a handful of Gibon malware samples in the wild and are providing this report in the event the malware becomes more widespread. Gibon is a new ransomware family named due to its USER-AGENT and name in the specimen’s ASCII strings. The malware was originally marketed on May 11 and 12 to several hacker forums for $500. Advertised functionality includes recursive encryption of all files that are on the computer, a README.txt file with instructions to the victim, and encryption/decryption keys which are sent to the admin panel and used for decryption. It is delivered via spam emails with a link to download a Microsoft Word document...READ MORE
Wapack Labs has cataloged and reported on ransomware variants in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Wapack Labs has cataloged and reported on ransomware variants in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
This TLP AMBER report is available only to Red Sky Alliance members.
Labels:
Gibon,
hacker forum,
malware,
ransomware
Reaper IoT Botnet Exploits and Mitigations

TLP AMBER ANNOUNCEMENT:
The Reaper IoT is a recently discovered Internet of Things (IoT) botnet that is proving to be more sophisticated and aggressive than the infamous 2016 Mirai IoT botnet. Despite the large botnet size reported by Tenable, there are very few IoT Reaper specimens available on Virus Total and other malware sharing sites. This is important to note as the number of specimens is often a reflection of the amount of infections. For example, there are currently thousands of Mirai specimens as opposed to a few dozen IoT Reaper specimens available. To date, no Distributed Denial of Service (DDoS) attacks have been observed with the IoT Reaper botnet. Wapack Labs analysts are providing this document as a summary of mitigations and indicators for Reaper malware and observed exploits. Wapack Labs recommends testing of all signatures before deployment...READ MORE
Wapack Labs has cataloged and reported on IoT and botnets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
This TLP AMBER report is available only to Red Sky Alliance members.
Monday, November 13, 2017
B.I.T.S Loader Attracting Cybercriminals

TLP AMBER ANNOUNCEMENT:
The Background Intelligent Transfer Service (BITS) is a legitimate Microsoft program used for creating and monitoring jobs over the network. Since it is a Windows legacy program it isn’t widely detected by AV solutions, making it attractive to cybercriminals for malware delivery and persistence. Recent emails targeting the Financial sector utilize BITS functionality by embedding it in heavily obfuscated Word documents, and with the use of LNK files. Monitoring BITS jobs in work environments is important to identify unwanted or unauthorized downloads and uploads. In the past, BITS was used to deliver banking trojans like DarkComet and GlobeImposter ransomware, and it is assessed with high confidence that it will continue to be utilized for both malware delivery and persistence, particularly against Windows based systems that would otherwise be considered highly locked down or security hardened. This report focuses on these two recent implementations of BITS, and looks at other ways BITS is leveraged in the wild...READ MORE
The Background Intelligent Transfer Service (BITS) is a legitimate Microsoft program used for creating and monitoring jobs over the network. Since it is a Windows legacy program it isn’t widely detected by AV solutions, making it attractive to cybercriminals for malware delivery and persistence. Recent emails targeting the Financial sector utilize BITS functionality by embedding it in heavily obfuscated Word documents, and with the use of LNK files. Monitoring BITS jobs in work environments is important to identify unwanted or unauthorized downloads and uploads. In the past, BITS was used to deliver banking trojans like DarkComet and GlobeImposter ransomware, and it is assessed with high confidence that it will continue to be utilized for both malware delivery and persistence, particularly against Windows based systems that would otherwise be considered highly locked down or security hardened. This report focuses on these two recent implementations of BITS, and looks at other ways BITS is leveraged in the wild...READ MORE
Wapack Labs has cataloged and reported on malware targeting the financial sector in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
This TLP AMBER report is available only to Red Sky Alliance members.
WWW.WAPACKLABS.COM
This TLP AMBER report is available only to Red Sky Alliance members.
Friday, October 27, 2017
Dark Web Site Selling ATM Malware

Wapack Labs observed ATM malware being sold on a dark web site. The malware targets all models of Wincore Nixdorf ATMs. The website explains that the Wincore 200xe ATMs are the easiest cash machines to exploit. The malware currently costs $1500.00 in Bitcoin for the first month (beginning 15 October 2017). After the first month, the ‘registration’ fee will be doubled. $1500.00 buys the buyer one credit, which is valid for a one time use on one ATM. To execute the attack users must log-in to their account on the website and receive a code (for one credit). The malware will then show the attacker the amount of cash in each money cassette that resides inside the ATM. The malware will then bypass the normal ATM system processes and the ATM will dispense all the bills in a desired cassette. The website also provides video links on their Tor site, demonstrating the method to fraudulently withdraw money, along with a free 10-page step-by-step Word document which explains how to use the malware. This guide describes in detail the tools required, software instructions, and details referencing different types of ATMs. This includes how the ATMs operate and how to find the interior USB ports...READ MORE
Wapack Labs has cataloged and reported on ATM malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
WWW.WAPACKLABS.COM
Tuesday, October 24, 2017
New Emotet Tactics Employing Embedded URL Links

Emotet is a credential stealing trojan with the ability to drop payloads and move laterally through networks. Emotet spreads by E-mail to addresses gained from the address books of previous victims. In October of 2017, Wapack Labs observed a new Emotet campaign targeting multiple industries. This recent campaign is characterized by changes in Tactics, Techniques, and Procedures (TTPs). These changes include the use of embedded URLs (or links) instead of attachments, and newly adopted obfuscation techniques. Emotet’s ability to spread to compromised email contacts aids in the increase of infections. E-mails propagated in this manner likely have a higher infection rate as they originate from a known contact. This report looks at the new TTPs observed including changes in delivery, obfuscation, and the Visual Basic embedded macros...READ MORE
Wapack
Labs has cataloged and reported on Emotet malware and campaigns in the past. An archive of related reporting can be
found in the Red Sky Alliance portal.
Tuesday, October 10, 2017
Auto-Update Malware Delivery TTP
TLP AMBER ANNOUNCEMENT: Malicious Microsoft Word documents are one of the most prevalent malware delivery mechanisms, and typically use embedded Visual Basic (VBA) macros to download and install malware on a victim’s machine. In late August and September 2017, Wapack Labs observed an uptick in an alternative Word doc based malware delivery method being leveraged in malicious email campaigns. The tactic involves using auto-updating links, instead of macros, to download additional malware payloads. Due to the prevalence of Office-based malware delivery, this new method will likely affect multiple industries, including Red Sky Alliance members. This report provides analysis on related specimens, including common artifacts and observed campaigns, as well as a generic mitigation that detects most variants...READ MORE
Wapack Labs has cataloged and reported malware delivery tactics in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
WWW.WAPACKLABS.COM
This TLP AMBER report is available only to Red Sky Alliance members.
Labels:
delivery,
links,
macro,
malicious email,
malware,
microsoft office,
ttp,
yara
Tuesday, September 12, 2017
Warhorse Botnet and Attack Framework
In August 2017, Wapack Labs uncovered a new botnet leveraging a recently released attack framework dubbed "Warhorse". The bots were observed delivering the GlobeImposter malware to numerous targets including those in the government, military, telecommunications, and energy sectors. Javascript downloaders such as Warhorse have become a popular delivery mechanism for multiple malware campaigns. The speed by which Warhorse was adopted by cyber criminals is notable with the campaign described in this report taking place only a few days after the project appeared on Github. While Warhorse currently has an above average detection ratio on VirusTotal, it is still undetected by several major anti-virus vendors. Furthermore, since it is likely that the delivery infrastructure is part of a larger botnet then there is a high probability the bots are being leveraged in other attacks. This report provides an early warning on this new botnet and details on the Warhorse attack framework...READ MORE
Wapack Labs has cataloged and reported extensively on botnets and malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
Labels:
anti-virus,
botnet,
cyber,
javascript,
malware
Monday, September 11, 2017
Profile: Arrested Chinese Cyber Actor Yu Pingan
TLP AMBER ANNOUNCEMENT: On 22 August 2017, a Chinese national named Yu Pingan was arrested and charged with cyber intrusions into four U.S. corporations between 2011 and 2014 that included the use of Sakula malware, known for its use in the major breaches of Anthem patient records and the Office of Personnel Management (OPM). Yu Pingan operates under the principle persona “Goldsun.” Analysts believe (high confidence) that he is in fact the Goldsun that was active at the Chinese hacker website Xfocus.net from 2004 to 2009. He is credited with and likely authored several pieces of malware that he posted during this period. His real identity remained unknown, but email addresses in some of his posts correspond to other accounts identified in the charges that led to his arrest. The charges against Yu Pingan do not identify any organization he was working for nor any connection to the Chinese government. Wapack Labs believes with medium confidence that Yu is affiliated with the Chinese civilian hacker group Wekby. The Chinese Government has not issued any statements and there has been no coverage of his arrest in official media...READ MORE
Wapack Labs has cataloged and reported extensively on China, Wekby, APT, and cyber intrusions in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
This TLP AMBER report is available only to Red Sky Alliance members.
Subscribe to:
Posts (Atom)


